Sign in

GitHub Security Lab

@securitylab.github.com
512 followers 1 following 121 posts

Securing open source software, together

PostsRepliesMedia
GitHub Security Lab @securitylab.github.com · 29/09/2026
How can AI help uncover real-world mobile security flaws? GitHub Security Lab used its open-source AI security agent to find and report 24 Android vulnerabilities—including issues affecting user privacy and account security. Read the research: github.blog/security/how...
github.blog
How we found 24 Android vulnerabilities using our open source AI security agent
A look at the targeted AI taskflows behind these findings, the bugs they uncovered, and how to run the same open-source agent on your own app.
110
GitHub Security Lab @securitylab.github.com · 24/09/2026
AI-powered fuzzing is here. GitHub Security Lab’s Fuzzing Taskflow automates harness creation, coverage improvement, crash triage, and vulnerability reporting for open source projects. Read github.blog/security/app...
github.blog
AI-powered fuzzing with the GitHub Security Lab Taskflow Agent
In this blog post, I explain how to use the new fuzzing taskflow based on the GitHub Security Lab Taskflow Agent AI framework.
021
GitHub Security Lab @securitylab.github.com · 21/09/2026
Open source maintainers, if you could secure your open source GitHub repo in less than 60 seconds, would you do it? 🚀 Introducing gh secure One command. Free. No security expertise required. gh.io/gh-secure
gh.io
GitHub - GitHubSecurityLab/gh-secure: A GitHub CLI extension to enable security features on repositories following best practices from GitHub Security Lab.
A GitHub CLI extension to enable security features on repositories following best practices from GitHub Security Lab. - GitHubSecurityLab/gh-secure
1103
GitHub Security Lab @securitylab.github.com · 04/09/2026
Here are the GitHub August bug bounty stats! 🐛 497 bounty reports submitted 👥 222 hackers participated in our program 💰 Awarded $104,402 in bounties Found a vulnerability? Submit it here: bounty.github.com
bounty.github.com
GitHub Security
Bug Bounty Program
000
GitHub Security Lab @securitylab.github.com · 27/08/2026
“Peter ignored me, so I was like, how else can I get his attention? Security.” 🔐 Sometimes the best path into open source is finding where your security expertise can help—and being ready to keep learning. Meet the maintainers building and securing OpenClaw: gh.io/openclaw-interview
gh.io
OpenClaw went viral. Meet the maintainers building and securing it.
OpenClaw is the fastest-growing project in GitHub history. Some of its maintainers share what they learned in the project's first six months.
000
GitHub Security Lab @securitylab.github.com · 13/08/2026
"AI security is not evolving in isolation. It is becoming part of the broader practice of building secure software. As that shift continues, maintainers will need practical education, trusted communities, and expert support that can evolve with them." github.blog/open-source/...
github.blog
What 50 open source projects taught us about security in the AI era
See how the projects in the GitHub Secure Open Source Fund combined AI-assisted workflows, maintainer expertise, and more to improve project security.
041
GitHub Security Lab @securitylab.github.com · 12/08/2026
🔐 Attending USENIX in Baltimore? Join Zach Steindler tomorrow for: Supply Chain Attacks on Open Source: What’s Happening, What Can We Do Today, and What’s Next 📅 August 13, 2026 🕟 4:30 PM 📍 Baltimore, MD #USENIX #OpenSourceSecurity #SupplyChainSecurity
010
GitHub Security Lab @securitylab.github.com · 06/08/2026
Hello Security researchers! Here are GitHub's July bug bounty stats! 💪 🐛 530 bounty reports submitted 👥 284 hackers participated in our program 💰 Awarded $267,652 in bounties Found a vulnerability? Submit it here: bounty.github.com Heading to DefCon? Come find us: x.com/GitHubSecuri...
bounty.github.com
GitHub Security
Bug Bounty Program
000
GitHub Security Lab @securitylab.github.com · 22/07/2026
Hey bounty hunters! GitHub updates its bug bounty program to improve how the company partners with the security research community. This update is designed to reduce ambiguity, prioritize the areas of highest risk, and improve the speed and quality of security outcomes. github.blog/security/nex...
github.blog
Next chapter: Restructuring GitHub's bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience.
010
GitHub Security Lab @securitylab.github.com · 10/07/2026
Are you in Krakow for EuroPython? Join Sylwia Budzynska for “Introduction to security research. Find a CVE with CodeQL” to learn how to look for vulnerabilities in code and query for them with CodeQL. 📆 Tuesday, 14th July ⏰ 13:45 📌 Kraków, Poland ep2026.europython.eu/session/intr...
ep2026.europython.eu
Introduction to security research. Find a CVE with CodeQL.
Learn how to find security vulnerabilities at Introduction to security research. Find a CVE with CodeQL tutorial
100
GitHub Security Lab @securitylab.github.com · 01/07/2026
6 GitHub security settings every maintainer should enable this week. These won't make your project unhackable. Nothing will. What they do is close the easy doors... the ones attackers try first. Free, fast, and worth the few minutes it takes. 🔗 github.blog/security/6-s...
github.blog
6 security settings every GitHub maintainer should enable this week
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors.
000
GitHub Security Lab @securitylab.github.com · 24/06/2026
What happens when you hand an AI agent its own tools, memory, and a path to production? Your job is to find the cracks before an attacker does. Play now: gh.io/scg Free. Open source. Get started in 2 minutes right from your browser.
000
GitHub Security Lab @securitylab.github.com · 03/06/2026
Attending BSides Vilnius? Don't miss 📌 @yarlob.bsky.social 's session "LLM-assisted vulnerability hunting: hype vs. reality" to hear about the practical experience of using LLM for finding vulnerabilities in OSS such as Signal or 7-Zip! 📅 June 4, 16:45 EEST 📍 Vilnius, Lithuania 👉 bsidesvilnius.lt
bsidesvilnius.lt
BSides Vilnius 2026 — Security Theater | Cybersecurity Conference in Lithuania
BSides Vilnius 2026 — community-driven cybersecurity conference in Lithuania. Workshops, talks, and CTF on 3–4 June at Kablys. Join the infosec community.
121
GitHub Security Lab @securitylab.github.com · 03/06/2026
Who's at DevTalks? Join @jkcso.bsky.social and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC. 📅 June 4, 14:00 EEST 📍 Bucharest, Romania 👉 www.devtalks.ro
devtalks.ro
DevTalks Romania
The largest expo conference for software developers and IT professionals in Romania, gathering over 8000 participants from all over the world.
000
GitHub Security Lab @securitylab.github.com · 30/05/2026
Attending AI DevCon? Join Joseph Katsioloudes and discover practical ways to use AI for security through 12 GitHub Copilot demos from secure coding, to informed supply chain decisions, and secure SDLC. 📅 June 1, 10:00 AM BST 📍 London, UK & Virtual 👉 tessl.io/speaker/jose...
000
GitHub Security Lab @securitylab.github.com · 27/05/2026
Proof of Concept for GHSL-2026-140 (CVE-2026-48095) in 7-Zip <= 26.00. A crafted archive shrinks a 256 MB buffer into 1 byte, overwrites a function pointer with file content, and redirects execution. Full weaponization needs an ASLR bypass. Fixed in 26.01. securitylab.github.com/advisories/G...
002
GitHub Security Lab @securitylab.github.com · 24/04/2026
On 25th April at 10AM, join @blazingwind.bsky.social for the workshop "Introduction to security research. Find a CVE with CodeQL" at the Linux Session organized by Akademickie Stowarzyszenie Informatyczne in Wroclaw, Poland! Check out more information on the conference's website: linuksowa.pl
linuksowa.pl
20. Sesja Linuksowa | Wrocław, Polska
Sesja Linuksowa to największa w Polsce konferencja poświęcona Wolnemu Oprogramowaniu oraz najnowszym trendom w systemach z rodziny GNU/Linux.
100
GitHub Security Lab @securitylab.github.com · 21/04/2026
Building with AI? 🤖 Then you won’t want to miss tomorrow’s @devoxx.fr workshop with @xcorail.bsky.social and @jkcso.bsky.social — all about how to build robust AI-powered applications. Shall we play a Game? LLM Security in Practice m.devoxx.com/events/devox... 📍 Paris 142 🗓️ April 22, 10.30am CET
m.devoxx.com
Devoxx Mobile Companion
Your ultimate companion for Devoxx conferences worldwide. Browse talks, speakers, schedules, and manage your personalized conference experience.
010
GitHub Security Lab @securitylab.github.com · 15/04/2026
Catch Shelby Cunningham on stage at CVE/FIRST VulnCon 2026 in Scottsdale, Arizona, at her panel “Supply Chains and Malware Campaigns: Is CVE the Right Way to Name the Game?”. Date: April 16, 2026 | 1:15–2:15 PM MST (UTC-7) Learn more: www.first.org/conference/v...
first.org
Program Agenda / CVE Program & FIRST VulnCon 2026
Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13–16, 2026
000
GitHub Security Lab @securitylab.github.com · 14/04/2026
AI agents that execute commands, browse the web, and coordinate with other agents are everywhere. But how do you know they're safe? We let you find out by hacking one yourself. Free, hands-on, and you can get started in under 2 minutes! Learn more in our latest blog. github.blog/security/hac...
github.blog
Hack the AI agent: Build agentic AI security skills with the GitHub Secure Code Game
Learn to find and exploit real-world agentic AI vulnerabilities through five progressive challenges in this free, open source game that over 10,000 developers have already used to sharpen their securi...
121
GitHub Security Lab @securitylab.github.com · 14/04/2026
Who’s at VulnCon? Join Sophia Sanles-Luksetich and Zachary Goldman at CVE/FIRST VulnCon 2026 in Scottsdale, Arizona. Learn more 🧵
first.org
Program Agenda / CVE Program & FIRST VulnCon 2026
Save the Date: CVE/FIRST VulnCon 2026 & Annual CNA Summit - Scottsdale (US), April 13–16, 2026
200
GitHub Security Lab @securitylab.github.com · 03/04/2026
A zero-permission Android app could read every photo, video, voice note, and document in your Signal chats. Downloaded Signal apk directly from Signal.org? You were vulnerable. securitylab.github.com/advisories/G...
securitylab.github.com
GHSL-2026-102: Unauthorized exfiltration of decrypted attachments in Signal through Intent redirection
Versions >= v6.38.0 and < v8.4.2 of the website flavor of Signal for Android (distributed at https://signal.org/android/apk) allows another installed app without any permissions to exfiltrate decrypte...
043
GitHub Security Lab @securitylab.github.com · 02/04/2026
Hidden feature in Signal? Not for attackers! An attacker with no admin privileges can delete any message in a group!
110
GitHub Security Lab @securitylab.github.com · 02/04/2026
Here are our March bug bounty stats! 🐛 380 bounty reports submitted 👩‍💻 260 hackers participated in our program 💰 Awarded $94,637 in bounties Found a vulnerability? Submit it here: t.co/HG2AqybW0p
t.co
https://bounty.github.com
000
GitHub Security Lab @securitylab.github.com · 27/03/2026
Reviewed advisories hit a four-year low, malware advisories surged, and CNA publishing grew—here’s what changed and what it means for your triage and response. Read Jonathan Evans's A year of open source vulnerability trends: CVEs, advisories, and malware github.blog/security/sup...
github.blog
A year of open source vulnerability trends: CVEs, advisories, and malware
Reviewed advisories hit a four-year low, malware advisories surged, and CNA publishing grew—here’s what changed.
000
GitHub Security Lab @securitylab.github.com · 26/03/2026
Software supply chain attacks are on the rise. Learn how open source contributors can use what GitHub Actions is building to help protect projects and the broader software community. github.blog/news-insight...
github.blog
What's coming to our GitHub Actions 2026 security roadmap
A look at GitHub Actions’ 2026 roadmap, outlining how secure defaults, policy controls, and CI/CD observability harden the software supply chain end to end.
011
GitHub Security Lab @securitylab.github.com · 23/03/2026
Dear open source community, read our communication on CanisterWorm, learn what GitHub does to protect the community and what you can do to secure your supply chain www.linkedin.com/pulse/commun...
linkedin.com
Communication on CanisterWorm
Dear open source community, On March 20th GitHub learned of a new supply chain attack through public disclosure by socket.dev dubbed CanisterWorm that affects more than 64 unique npm packages.
000
GitHub Security Lab @securitylab.github.com · 06/03/2026
Sign in with ANY password: How we used AI to break into a popular chat application, and other high-impact vulnerabilities. Read "How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework" github.blog/security/how...
github.blog
How to scan for vulnerabilities with GitHub Security Lab’s open source AI-powered framework
GitHub Security Lab Taskflow Agent is very effective at finding Auth Bypasses, IDORs, Token Leaks, and other high-impact vulnerabilities.
011
GitHub Security Lab @securitylab.github.com · 06/03/2026
Hello hackers! Here are our February bug bounty stats! 🐛 200 bounty reports submitted 👩‍💻 144 hackers participated in our program 💰 Awarded $48,589 in bounties Found a vulnerability? Submit it here: t.co/HG2AqybW0p
t.co
https://bounty.github.com
000
GitHub Security Lab @securitylab.github.com · 19/02/2026
If you're at #DeveloperWeek and you care about open source security, there is a session you must attend. We have been contributing to secure open source for 6 years and @xcorail.bsky.social will share with you the lessons learned from this journey! How GitHub Secures Open Source, PRO stage, 1pm.
010
GitHub Security Lab @securitylab.github.com · 09/02/2026
Here are our January bug bounty stats! 🐛 182 bounty reports submitted 👩‍💻 112 hackers participated in our program 💰 Awarded $76,269 in bounties Found a vulnerability? Submit it here: t.co/HG2AqybW0p.
t.co
https://bounty.github.com
010
GitHub Security Lab @securitylab.github.com · 20/01/2026
Learn how we triage security alerts in GitHub Actions and JavaScript projects with the new GitHub Security Lab Taskflow Agent, and leverage LLM to focus on the exploitable vulnerabilities. github.blog/security/ai-...
github.blog
AI-supported vulnerability triage with the GitHub Security Lab Taskflow Agent
Learn how we are using the newly released GitHub Security Lab Taskflow Agent to triage categories of vulnerabilities.
011
GitHub Security Lab @securitylab.github.com · 14/01/2026
Excited to share our open source agentic framework for security research, a collaborative framework that lets the community share AI "taskflows”! Read @kevinbackhouse.bsky.social 's blog post for details and a demo. Join us in strengthening open-source security! github.blog/security/com...
github.blog
Community-powered security with AI: an open source framework for security research
Announcing GitHub Security Lab Taskflow Agent, an open source and collaborative framework for security research with AI.
012
GitHub Security Lab @securitylab.github.com · 06/01/2026
We wrapped up 2025 on a high note—here are the bug bounty stats for December! ✅ 151 bounty reports submitted 👥110 hackers participated in our program 💰Awarded $48,367 in bounties Found a vulnerability? Submit it here: bounty.github.com.
bounty.github.com
GitHub Security
Bug Bounty Program
030
GitHub Security Lab @securitylab.github.com · 30/12/2025
Learn why some vulnerabilities resist to fuzzing and persist in long-enrolled OSS-Fuzz projects, and how you can find them! github.blog/security/vul...
110
GitHub Security Lab @securitylab.github.com · 23/12/2025
In just 17 minutes, @yarlob.bsky.social shares his knowledge about securing GitHub Actions, drawing from hands-on experience uncovering hundreds of real-world vulnerabilities. The talk wraps up with FREE tools to automate GitHub Actions security you can start using TODAY. gh.io/secure-githu...
gh.io
Resources
Securing open source software, together.
000
GitHub Security Lab @securitylab.github.com · 23/12/2025
GitHub Security Lab discovered a critical vulnerability in WooCommerce. We’d like to thank WooCommerce/Automattic for their incredibly quick response and fix of the vulnerability. If you are using WooCommerce, please update. For more info see: developer.woocommerce.com/2025/12/22/s...
developer.woocommerce.com
Store API Vulnerability Patched in WooCommerce 8.1+ - What You Need To Know
A critical vulnerability in WooCommerce 8.1+ has been patched. We strongly recommend updating immediately.
031
GitHub Security Lab @securitylab.github.com · 01/12/2025
Hello Hackers! Here are our November bug bounty stats! 🐛146 bounty reports submitted 👩‍💻102 hackers participated in our program 💰Awarded $93,068 in bounties Found a vulnerability? Submit it here: bounty.github.com
t.co
https://bounty.github.com
000
GitHub Security Lab @securitylab.github.com · 19/11/2025
Attending AI Native DevCon? Join @jkcso.bsky.social and discover practical ways to use AI for security through 14 live GitHub Copilot demos from secure coding, to supply chain decisions, to MCP servers. 📅 November 19, 11:40 AM EST 📍 Industry City, Kings County, NY + online 👉 ainativedev.io/devcon
Flyer of the conference session. Title: Code Security Reinvented: Navigating the era of AI. Track: TOOLS IN ACTION. Speaker: Jospeh Katsioloudes, Cyber Security Specialist at GitHub.
000
GitHub Security Lab @securitylab.github.com · 13/11/2025
Join us at @nerdearla.bsky.social to discover how GitHub secures the open source software we rely on. From security research and education to free tools and programs that have strengthened the security of hundreds of projects. 📅 November 14, 11 AM CET 📍 LaNaveMadrid + free streaming 👉 nerdearla.es
001
GitHub Security Lab @securitylab.github.com · 11/11/2025
🚀 GitHub is making Actions more secure by default We recently announced upcoming changes to the pull_request_target event and environment protection rules to make GitHub Actions more secure by default. We’ve opened a discussion to gather feedback 👇 🔗 github.com/orgs/communi...
github.com
Towards a secure by default GitHub Actions · community · Discussion #179107
Why are you starting this discussion? Product Feedback What GitHub Actions topic or product is this about? Workflow Configuration Discussion Details Today, GitHub announced upcoming changes to the ...
064
GitHub Security Lab @securitylab.github.com · 04/11/2025
Here are our October bug bounty stats! 🐛 162 bounty reports submitted 🎃 121 hackers participated in our program 💰 Awarded $78,968 in bounties Found a vulnerability? Submit it here: bounty.github.com
bounty.github.com
GitHub Security
Bug Bounty Program
030
GitHub Security Lab @securitylab.github.com · 28/10/2025
Building with AI? 🤖 Then you won’t want to miss tomorrow’s #GitHubUniverse workshop with Joseph Katsioloudes and Rahul Zhade — all about how to build secure LLM-powered applications. 📍 Fort Mason Center for Arts & Culture 🗓️ Oct 29, 1:15–2:45 PM PDT
010
GitHub Security Lab @securitylab.github.com · 24/10/2025
🎉 It’s Friday at #EkoParty! Join us at the GitHub booth at 15:30 for the GitHub Quiz 🧠 Test your security knowledge, win exclusive GitHub swag, grab some stickers, and chat with our experts! 👉 gh.io/eko
gh.io
GitHub Security Lab
Securing open source software, together.
021
GitHub Security Lab @securitylab.github.com · 22/10/2025
Aprende como usar LLMs para mejorar el proceso de fuzzing en la charla de Antonio Morales en #ekoparty2025 📅 Jueves, 23 Oct, 15:30 AST
000
GitHub Security Lab @securitylab.github.com · 22/10/2025
👋 Hola Argentina! We’re thrilled to be at #EkoParty this week! If you’re around, swing by the GitHub booth — grab some stickers, play our security games, and chat with our experts about all things open source & security. See you there 👉 gh.io/eko
gh.io
GitHub Security Lab
Securing open source software, together.
020
Reposted by GitHub Security Lab
GitHub @github.com · 20/10/2025
The internet was on fire. 🔥 One small library affecting billions of systems. Log4Shell was the biggest security vulnerability of all time. Now, Log4J maintainer, Christian Grobmeier tells us what it felt like inside the flames 👉 github.blog/open-source/...
510918
GitHub Security Lab @securitylab.github.com · 13/10/2025
Are you in Warsaw for The Hack Summit Warsaw? Join Sylwia Budzynska for an introductory talk about security research, static analysis, and CodeQL: "From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL" 📆 October 14, 11:20 CEST Track: Security in Software Development & DevSecOps
Flyer from the conference The Hack Summit announcing a presentation: 
Sylwia Budzynska, GitHub Security Researcher
From One Bug to Hundreds: Scaling Vulnerability Research with CodeQL
000
GitHub Security Lab @securitylab.github.com · 08/10/2025
Here are our September bug bounty stats! ✅ 166 bounty reports submitted 👥 120 hackers participated in our program 💰 Awarded $113,008 in bounties Found a vulnerability? Submit it here: t.co/HG2AqybW0p.
t.co
https://bounty.github.com
000
GitHub Security Lab @securitylab.github.com · 30/09/2025
⏱️ Maintainers, we know you don’t have time to research every security best practice. That’s why we’ve made it simple: ✅ 15 minutes ✅ No security expertise required ✅ Free for open source ✅ Quick wins with long-term impact Protect your project now at gh.io/protect-your-project
gh.io
Protect Your Project
Securing open source software, together.
0112